I executed look2me and it finded some stuff but xxwww.dll is still there and imposible to delete:
HERE IS THE LOOK2ME-DESTROYER TXT: -------------------------------------------------------------------
Look2Me-Destroyer V1.0.12
Scanning for infected files.....
Scan started at 09/04/2006 10:08:05
Infected! C:\WINDOWS\system32\n6l8lg3u16.dll
Infected! C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP360\A0107693.dll
Infected! C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP360\A0107726.dll
Infected! C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP361\A0107817.dll
Infected! C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP361\A0107847.dll
Infected! C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP361\A0107850.dll
Infected! C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP361\A0107858.dll
Infected! C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP361\A0107874.dll
Infected! C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP362\A0108100.dll
Infected! C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP362\A0108114.dll
Infected! C:\WINDOWS\system32\acsnt.dll
Infected! C:\WINDOWS\system32\agicap32.dll
Infected! C:\WINDOWS\system32\ari2dvaa.dll
Infected! C:\WINDOWS\system32\dgskadp.dll
Infected! C:\WINDOWS\system32\dHdim700.dll
Infected! C:\WINDOWS\system32\dnpo0173e.dll
Infected! C:\WINDOWS\system32\dnro0193e.dll
Infected! C:\WINDOWS\system32\DT240.dll
Infected! C:\WINDOWS\system32\fp6403jqe.dll
Infected! C:\WINDOWS\system32\irpol5731.dll
Infected! C:\WINDOWS\system32\ktdcz1.dll
Infected! C:\WINDOWS\system32\li_encrypt.dll
Infected! C:\WINDOWS\system32\meperf.dll
Infected! C:\WINDOWS\system32\mjxclu.dll
Infected! C:\WINDOWS\system32\mpcertui.dll
Infected! C:\WINDOWS\system32\mzdscli.dll
Infected! C:\WINDOWS\system32\n4r20e9oeh.dll
Infected! C:\WINDOWS\system32\n6l8lg3u16.dll
Infected! C:\WINDOWS\system32\ntth.dll
Infected! C:\WINDOWS\system32\rXsctrs.dll
Infected! C:\WINDOWS\system32\tcddd.dll
Infected! C:\WINDOWS\system32\wtnhttp.dll
Attempting to delete infected files...
Attempting to delete: C:\WINDOWS\system32\n6l8lg3u16.dll
C:\WINDOWS\system32\n6l8lg3u16.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP360\A0107693.dll
C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP360\A0107693.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP360\A0107726.dll
C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP360\A0107726.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP361\A0107817.dll
C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP361\A0107817.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP361\A0107847.dll
C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP361\A0107847.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP361\A0107850.dll
C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP361\A0107850.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP361\A0107858.dll
C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP361\A0107858.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP361\A0107874.dll
C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP361\A0107874.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP362\A0108100.dll
C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP362\A0108100.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP362\A0108114.dll
C:\System Volume Information\_restore{6851C1F0-AC29-468A-BD4F-23A48FEB3BAC}\RP362\A0108114.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\acsnt.dll
C:\WINDOWS\system32\acsnt.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\agicap32.dll
C:\WINDOWS\system32\agicap32.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\ari2dvaa.dll
C:\WINDOWS\system32\ari2dvaa.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\dgskadp.dll
C:\WINDOWS\system32\dgskadp.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\dHdim700.dll
C:\WINDOWS\system32\dHdim700.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\dnpo0173e.dll
C:\WINDOWS\system32\dnpo0173e.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\dnro0193e.dll
C:\WINDOWS\system32\dnro0193e.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\DT240.dll
C:\WINDOWS\system32\DT240.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\fp6403jqe.dll
C:\WINDOWS\system32\fp6403jqe.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\irpol5731.dll
C:\WINDOWS\system32\irpol5731.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\ktdcz1.dll
C:\WINDOWS\system32\ktdcz1.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\li_encrypt.dll
C:\WINDOWS\system32\li_encrypt.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\meperf.dll
C:\WINDOWS\system32\meperf.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\mjxclu.dll
C:\WINDOWS\system32\mjxclu.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\mpcertui.dll
C:\WINDOWS\system32\mpcertui.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\mzdscli.dll
C:\WINDOWS\system32\mzdscli.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\n4r20e9oeh.dll
C:\WINDOWS\system32\n4r20e9oeh.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\n6l8lg3u16.dll
C:\WINDOWS\system32\n6l8lg3u16.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\ntth.dll
C:\WINDOWS\system32\ntth.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\rXsctrs.dll
C:\WINDOWS\system32\rXsctrs.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\tcddd.dll
C:\WINDOWS\system32\tcddd.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\wtnhttp.dll
C:\WINDOWS\system32\wtnhttp.dll Deleted successfully!
Making registry repairs.
Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\App Management
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{7734A382-6D46-4053-B446-37A66B94B2C0}"
HKCR\Clsid\{7734A382-6D46-4053-B446-37A66B94B2C0}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{EB5CF0F4-2357-40DE-9460-465C4C53A7EF}"
HKCR\Clsid\{EB5CF0F4-2357-40DE-9460-465C4C53A7EF}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{1C9FD646-C814-474E-8F15-7EF3C728CE51}"
HKCR\Clsid\{1C9FD646-C814-474E-8F15-7EF3C728CE51}
Restoring Windows certificates.
Replaced hosts file with default windows hosts file
Restoring SeDebugPrivilege for Administradores - Succeeded
AND HERE THE NEXT HIJACKTHIS LOG ---------------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 10:17:20, on 09/04/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Archivos de programa\Network Associates\Common Framework\FrameworkService.exe
C:\Archivos de programa\Network Associates\VirusScan\Mcshield.exe
C:\Archivos de programa\Network Associates\VirusScan\VsTskMgr.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\ntsec.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Archivos de programa\Archivos comunes\Real\Update_OB\realsched.exe
C:\Archivos de programa\Network Associates\VirusScan\SHSTAT.EXE
C:\Archivos de programa\Network Associates\Common Framework\UpdaterUI.exe
C:\Archivos de programa\Archivos comunes\Network Associates\TalkBack\TBMon.exe
C:\Archivos de programa\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Archivos de programa\Telefonica\KitAIM\AimMon.exe
C:\Temp\delete paytime\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.geekstogo.com/O2 - BHO: (no name) - {20D57A66-F7DF-467d-907B-9B7F4A118AB7} - C:\WINDOWS\SYSTEM32\xxwww.dll
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Archivos de programa\Archivos comunes\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ShStatEXE] "C:\Archivos de programa\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Archivos de programa\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Archivos de programa\Archivos comunes\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [AgenteADSL_15] C:\Archivos de programa\Telefonica\KitAIM\AimExDll.exe AimGestA.dll 9 run
O4 - HKLM\..\Run: [Zone Labs Client] C:\Archivos de programa\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PcSync] C:\Archivos de programa\Nokia\Nokia PC Suite 5\PcSync2.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1144446099482O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1144446257940O20 - Winlogon Notify: xxwww - C:\WINDOWS\SYSTEM32\xxwww.dll
O23 - Service: Servicio de registro de McAfee (McAfeeFramework) - Network Associates, Inc. - C:\Archivos de programa\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Archivos de programa\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Archivos de programa\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: NTSec(ntsec) (NTSec) - Unknown owner - C:\WINDOWS\system32\ntsec.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Thanks a lot for your help!!
Pedro